The way I’m reading this article, this is mostly a Github thing:
The malware allows TeamPCP’s hackers to steal credentials (on github) that let them publish malicious versions of those software development tools, too (on github). The cycle repeats, and TeamPCP’s collection of breached networks grows.
The way I’m reading this article, this is mostly a Github thing: